skip to content

Permissions and Users

The Unix permission model: rwx bits and their octal shorthand, setuid/setgid/sticky, ACLs, the account files behind users and groups, and sudoers. Expect to be asked what 4755 means and why a setuid binary deserves suspicion.

part ofLinux & distributionsoverview, primer and where to startread it →
on this pageshow

questions

page 2 of 2

A Linux user types the correct password and is still refused at login, with no message about a wrong password. Explain how PAM structures the login path and which stage rejects an otherwise-valid password.

level: seniorimportance: nice to knowfreq 38%

basics

~20 s

PAM splits authentication into four independent stacks: auth (are you who you say), account (are you allowed right now), password (changing the secret) and session (setting the session up). A correct password that still fails is almost always rejected by the account or session stack.

open as a page

You set the access-control conventions for a fleet of Linux servers. When do you accept POSIX ACLs on shared directories, and when do you insist the access be expressed as group membership instead?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

Use group membership as the default, because it is managed centrally and audited in one place; use ACLs for genuine per-path exceptions that would otherwise force a single-purpose group. Any ACL you accept should be declared in configuration management, not applied by hand.

open as a page

Your platform standard requires every Linux service to run under a non-root account with a minimal capability set. What does that requirement actually buy you, where does the capability model stop being a real boundary, and how do you decide when a workload needs something stronger?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Dropping to a minimal capability set removes specific kernel privileges and shrinks what a compromised process can escalate to. It is not a containment boundary: it does not restrict ordinary file access, syscall surface or network reach, and one root-equivalent capability undoes the whole set.

open as a page

showing 31–33 of 33